From The Hacker News · 40 stories
Zombie Card Attack Revives Expired Visa Contactless Cards for Purchases
Researchers at the University of Massachusetts Amherst demonstrated a "Zombie Card" attack that allows expired Visa contactless credit cards to be used for in-store purchases by rewriting the expiration date read by a point-of-sale terminal. This attack requires physical access to the card and a man-in-the-middle relay, and it exploits how Visa's Kernel 3 processes expiration dates, which could lead to unauthorized transactions if banks do not re-check expiry during authorization.
CDN Tsunami Attacks Exploit HTTP/3 Translation for DoS Amplification
Cybersecurity researchers disclosed "CDN Tsunami" denial-of-service attacks that exploit how major CDNs convert HTTP/3 client requests to HTTP/1.1 for origin servers. This method amplifies low-bandwidth requests by up to 350x against the origin, affecting six major CDN providers.
NASA AIT-GUI Flaws Allow Unauthenticated Spacecraft Command Execution
Security researchers at Cycode discovered critical flaws in NASA/JPL's AIT-GUI, an open-source operator console for spacecraft, that could allow unauthenticated attackers to issue arbitrary commands. The vulnerabilities, rated 9.4 CVSS, affect versions 2.5.1 and earlier and have been patched in version 2.5.2. This impacts the security of ground data systems used to control spacecraft and instruments.
Snowflake GitHub Actions Flaw Allowed Command Injection via Crafted Issues
Cybersecurity researchers at Wiz discovered a GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository. This flaw allowed command execution through crafted GitHub issues, potentially exposing internal Jira credentials. Snowflake quickly patched the vulnerability, confirming no evidence of unauthorized access.
Unisoc VoLTE Exploit Chain Grants Full Android Kernel Access, No Fix Available
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that allows full Android kernel access on devices using Unisoc modem firmware via a VoLTE video call. The chipset maker has not provided a fix for this vulnerability, which affects devices from Motorola, Realme, and Xiaomi.
Threat Actors Acquire Expired Domains to Redirect Traffic to Scams and Malware
Threat actors are acquiring expired domains, termed "dropcatch domains," to exploit their inherited reputation and traffic for redirecting users to scams and malware. This practice accounts for nearly 20% of all daily new domain registrations, posing a significant security risk by leveraging previously legitimate web addresses.
Mustang Panda's CoolClient Backdoor Now Uses Signed Windows Kernel-Mode Rootkit
The threat actor Mustang Panda (HoneyMyte) has updated its CoolClient backdoor to include a signed Windows kernel-mode rootkit, enhancing its ability to hide malicious activity. This new component allows the malware to conceal processes, files, registry objects, and C2 network information, making detection and removal more difficult for cybersecurity defenses.
China-Linked Jewelbug Group Uses XG-Web for Espionage and Crypto Fraud
The China-linked threat actor Jewelbug conducts cyber espionage against governments and militaries while simultaneously engaging in cryptocurrency fraud, utilizing a single control panel called XG-Web. This group operates parallel missions, targeting entities in the Middle East, Southeast Asia, and South Asia for espionage, and Chinese-speaking victims for financial gain through crypto fraud.
New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure
A new backdoor named PATCHCORD is targeting Afghan telecom providers and South Asian critical infrastructure organizations. This campaign, attributed to the Pakistan-aligned APT36, uses sector-specific lures like fake VPN installers and impersonated government domains to deliver malware capable of remote command execution and data exfiltration.
Kimwolf v7 Android Botnet Uses HTTP/2 DDoS with Browser Fingerprints, Enhances C2 Resilience
Cybersecurity researchers have identified Kimwolf v7, a new version of the Android and IoT botnet, which now employs HTTP/2 DDoS attacks that mimic legitimate browser traffic and uses Ethereum Name Service (ENS) for more resilient command-and-control (C2) infrastructure. This development makes the botnet's attacks harder to detect and its C2 more difficult to disrupt, posing an increased threat to Android TV boxes and Linux IoT devices.
Malicious SIM Cards Can Execute Code on Cellular IoT Devices and Some Phones
Researchers discovered that malicious SIM cards can force some cellular IoT modules and phones to run arbitrary commands, potentially leading to full device takeover. This vulnerability affects devices like EV chargers and industrial routers, primarily impacting machine-to-machine hardware with accessible SIM trays. Qualcomm and Quectel are addressing the issue, but no public advisories have been released.
Researchers Create Fake Startup to Identify Suspected North Korean IT Workers
Security researchers established a fictitious cryptocurrency startup, advertised developer positions, and hired three individuals believed to be North Korean operatives. This operation aimed to study the methods used by North Korean IT workers to gain employment and access to company systems, highlighting the risks posed to businesses.
Malicious VS Code Extension "Solidity Pro" Steals Crypto Wallets and Credentials
Cybersecurity researchers identified a malicious Visual Studio Code extension, Solidity Pro, that exfiltrates cryptocurrency wallets, API keys, and other credentials. The extension used obfuscation and delayed activation to bypass security checks and steal sensitive user data.
Linux SCTP Flaw Allows Local Root Privilege Escalation and Container Escape
A use-after-free vulnerability in the Linux kernel's Stream Control Transmission Protocol (SCTP) networking code, present since 2008, allows local users to gain root privileges and escape containers. Tencent researchers demonstrated the exploit, and fixes have been released in recent stable kernel versions.
NatJack Attack Class Hijacks TCP Sessions and Spoofs DNS by Manipulating NAT Tables
Security researcher Malcolm Stagg disclosed NatJack, a new attack class that manipulates Network Address Translation (NAT) connection states to hijack TCP sessions, spoof DNS, and exhaust NAT tables. This research, presented at Black Hat USA 2026, impacts independently developed NAT implementations, including Windows and Linux, and requires an attacker to have privileged access behind the same NAT as the victim.
PortSwigger's AI-assisted HTTP Terminator discovers new desync techniques and Apache zero-day
PortSwigger's AI-assisted research system, HTTP Terminator, identified new HTTP desynchronization techniques and a zero-day vulnerability in Apache Traffic Server. This research highlights the potential for AI to uncover novel attack vectors and improve the reliability of existing exploits like Response Queue Poisoning (RQP).
New Zapscape KVM Flaw Allows L1 Guest Code to Escape to Linux Hosts
A new Linux kernel vulnerability, tracked as CVE-2026-64561 and named Zapscape, allows an attacker with kernel privileges in an L1 guest VM to escape KVM isolation and execute code on the host. This flaw affects KVM/x86's shadow memory management unit and has a merged upstream fix, requiring administrators to update their kernels.
Weekly Security Roundup: China-linked telecom risks, ClickOnce phishing, and npm supply chain attack
This week's security report highlights several active threats, including a U.S. Congressional committee report on China-linked telecom infrastructure risks, a new ClickOnce phishing chain used by SideWinder, and an npm supply chain attack involving 846 malicious packages. These incidents demonstrate ongoing vulnerabilities in telecommunications, software delivery, and supply chain security, posing risks to various organizations and users.
Weak CryptoJS RNG Led to $5.7 Million in Crypto Wallet Drains Across Five Apps
Coinspect identified that the CryptoJS.lib.WordArray.random() function, introduced 12 years ago, contained a weak random number generator that allowed for the theft of approximately $5.7 million from five crypto wallet applications. This vulnerability reduced the entropy of recovery phrases, making them guessable and compromising user funds.
Attackers use SQL injection to compile and run 'khunt' toolkit within Oracle databases for SYSTEM access
Attackers exploited a SQL injection vulnerability in a public-facing web application to gain access to an Oracle database, then compiled and ran a post-exploitation toolkit named 'khunt' directly within the database engine. This technique allowed them to achieve SYSTEM-level code execution on the underlying Windows server without writing executables to disk, bypassing typical endpoint detection and response systems.
Veeam, Terraform MCP, and Django Patch Critical Vulnerabilities, Including CVSS 10.0 Flaw
HashiCorp, Veeam, and the Django Software Foundation have released patches for 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django, including a critical cross-tenant flaw in HashiCorp's MCP server rated 10.0 CVSS. These updates are crucial for operators to secure their systems against potential exploitation, as several flaws could lead to credential compromise or remote code execution.
Kali365 Phishing Kit Exploits Microsoft Authentication to Target US Organizations
A new phishing kit named Kali365 is actively targeting US organizations by weaponizing legitimate Microsoft authentication processes. It tricks victims into approving attacker-controlled device codes on Microsoft's own login page, granting attackers continued access to Microsoft 365 resources like email and documents. This method bypasses typical phishing indicators, increasing the risk of financial fraud, data exposure, and operational disruption for affected businesses.
Leaked n8n API Tokens Exposed 321 Instances to Credential Theft
GitGuardian researchers discovered 321 n8n instances that accepted API tokens exposed in public GitHub commits, allowing unauthorized access to sensitive data and downstream credentials. This exposure affects a significant portion of reachable instances and demonstrates how attackers can bypass security measures without exploiting software vulnerabilities.
QuickFox VPN Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Cybersecurity researchers have uncovered a supply chain attack targeting QuickFox, a VPN service, that has been ongoing since at least August 2025. The attack involved a modified Windows installer delivering the FDMTP backdoor, attributed to the Chinese state-sponsored threat actor Mustang Panda. This incident highlights the ongoing risk of supply chain compromises, particularly for software used by specific user demographics.
cPanel Patches Critical Flaw Allowing Hosting Customers to Execute SQL as Database Root
cPanel has released a security update to address CVE-2026-58048, a critical vulnerability that allowed authenticated hosting customers to execute SQL commands with root privileges within the database context. This flaw could lead to a server compromise depending on the system configuration and affects all supported versions of cPanel & WHM, along with WP Squared.
Chinese Threat Actor Uses Leaked DarkSword Exploit Kit to Deploy GHOSTBLADE on iOS
A Chinese threat actor is using a publicly leaked version of the DarkSword exploit kit to target Apple iOS devices, deploying the GHOSTBLADE information-stealing malware. The campaign involves over 100 web properties, many impersonating AWS sign-in pages, to deliver the exploit chain. This development indicates the broader proliferation of the DarkSword kit following its source code leak, enabling more threat actors to conduct iOS attacks.
Thermo Fisher Patches DNA File Tampering Flaw in Human Identification Software
Thermo Fisher Scientific has released patches for a high-severity vulnerability (CVE-2026-17583) in its Applied Biosystems human identification software that could allow nearly undetectable alteration of DNA data files. The flaw, rated 8.2 CVSS v4.0, affects five supported product lines and could enable malicious actors to combine or modify DNA profiles without detection, impacting forensic and diagnostic integrity.
Chinese-Speaking Hackers Target Central Asian Governments with New OctLurk and SilkLurk Backdoors
A Chinese-speaking threat actor has been targeting government organizations in Central Asia since January 2025, deploying new backdoors named OctLurk and SilkLurk. These attacks compromise various sectors, including healthcare and government ministries, to steal credentials and perform remote actions, highlighting an ongoing cyber espionage campaign.
Researchers Identify 84 Flaws in 4G and 5G Core Networks, Including Session Hijacking
Researchers from Nanyang Technological University have disclosed 84 security vulnerabilities in 4G and 5G core networks, stemming from implicit trust errors between network functions. These flaws could enable denial-of-service attacks and session hijacking, impacting both research testbeds and commercial deployments. The findings highlight increased attack surfaces due to the transition to cloud-native deployments.
Microsoft Copilot for Word Vulnerable to Hidden Prompt Injection, Copies Instructions to Output
A security researcher discovered that Microsoft 365 Copilot for Word can be manipulated by hidden instructions within a document, causing it to alter content and then copy those hidden instructions into the generated output. This vulnerability allows malicious documents to influence Copilot's behavior and conceal the changes, posing a risk for data integrity and information disclosure in AI-assisted document creation.
Silver Fox Group Uses New 3-Driver BYOVD Chain to Deliver ValleyRAT to Japanese Manufacturer
The Chinese cybercrime group Silver Fox has deployed a new three-driver Bring Your Own Vulnerable Driver (BYOVD) attack chain against a Japanese industrial manufacturing organization to install ValleyRAT for persistent remote access. This campaign introduces previously unreported vulnerable drivers and combines them with DLL sideloading and defense evasion techniques to maintain control and bypass security controls. The use of multiple drivers enhances the attack's resilience and adaptability across different environments.
Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
Cybersecurity researchers have uncovered a nine-year fraud campaign that uses cloned websites of major Russian companies to steal advance payments from international firms. The scheme targets B2B organizations, primarily in CIS countries, by tricking them into making payments to fraudulent bank accounts for non-existent goods.
73% of Organizations Unprepared for Major Cyberattacks, Citing Coordination Gaps
A new report based on a survey of 600 IT security decision-makers reveals that 73% of organizations are not fully ready for a significant cyberattack, despite having incident response plans and tools. The findings highlight a critical gap in coordination, visibility, and executive alignment, which hinders effective incident response under pressure.
Flying Eagle Android RAT Source Code Circulates, 170 Servers Identified
The source code for the Flying Eagle Android remote access trojan (RAT) is being distributed via criminal Telegram channels, with researchers identifying 170 internet servers hosting its control panels. This RAT framework is linked to a fake Chinese public security application and can capture payment passwords, record screens, and access cameras, posing a significant threat to Android users.
Tengu Botnet Uses Hardware Watchdog to Reboot Compromised Linux Devices
A new Mirai-derived botnet named Tengu can force a reboot of compromised Linux devices by abusing the hardware watchdog if its main process is terminated. This mechanism allows its other persistence methods to relaunch the botnet, making it more resilient against defense efforts. The botnet supports 25 DDoS methods and can execute shell commands, collect data, and update itself.
OpenWrt Patches Critical DHCPv6 Flaw Allowing Remote Code Execution as Root
OpenWrt released versions 24.10.8 and 25.12.5 to fix a critical DHCPv6 stack overflow vulnerability (CVE-2026-53921) that could allow unauthenticated attackers to execute code as root. This vulnerability affects the odhcpd service, which runs by default on OpenWrt devices, and is particularly concerning for embedded hardware lacking common exploit mitigations.
Nimbus Manticore Deploys New NightLedger Backdoor and WebSocket Tunnelers in Attacks
The Iranian state-backed hacking group Nimbus Manticore is using a new Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, in recent attacks targeting organizations across the Middle East, Africa, and South Asia. These tools allow the group to maintain covert access and conduct reconnaissance, command execution, and data exfiltration on compromised systems.
STAR Labs Discloses Linux Kernel Exploit (CVE-2026-53264) Aided by AI
STAR Labs researcher Lee Jia Jie published a Linux kernel exploit (CVE-2026-53264) for a use-after-free race condition in the network traffic-control subsystem, stating that AI assisted in its discovery and development. This local privilege escalation vulnerability affects Linux kernels from version 4.14 and has been patched in recent stable branches, requiring users to update their distributions.
Cruciferra Crypter Uses BYOVD and Process Ghosting to Evade Detection
A new analysis by Proofpoint details Cruciferra, a sophisticated crypter service used by various cybercriminal groups to deliver malware. Cruciferra employs techniques like BYOVD and Process Ghosting to evade detection and analysis, complicating forensic efforts and static analysis.
New TELESHIM Malware Uses Telegram for C2 in Attacks Against Middle East Governments
Cybersecurity researchers at Zscaler ThreatLabz identified a new cyber campaign by an East Asian threat actor targeting Middle Eastern government entities. This campaign deploys previously undocumented malware families, including TELESHIM, which abuses the Telegram API for command-and-control communications. The use of Telegram for C2 allows the malware to blend with legitimate network traffic, posing a challenge for detection and defense.